SAML2 Library Vulnerability in SimpleSAMLphp Affects XML Signature Processing
CVE-2026-49289
What is CVE-2026-49289?
The SimpleSAMLphp SAML2 library, utilized for handling SAML2 features, has a security weakness in versions 4.19.2 and 4.20.2 that allows an attacker to control XPath transforms while processing specially crafted XML signatures in SAML messages. This flaw enables a remote unauthenticated attacker to consume excessive processing resources, potentially leading to a denial of service for any system that depends on the SimpleSAMLphp or the SAML2 library. The issue has been addressed in versions 4.19.3 and 4.20.3, where mitigations limit the number of transforms allowed by restricting algorithms to those specified by the SAML 2.0 Core specification and explicitly disallowing XPath transforms.
Affected Version(s)
saml2 >= 4.19.2, < 4.19.3 < 4.19.2, 4.19.3
saml2 >= 4.20.2, < 4.20.3 < 4.20.2, 4.20.3
